6.5
CVSSv2

CVE-2007-2082

Published: 18/04/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and previous versions allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.

Vulnerable Product Search on Vulmon Subscribe to Product

myblog myblog